OXLOADER: new loader evading detection to drop infostealer
June 19, 2026, 8:39 a.m.
Description
A previously undocumented Windows loader designated as OXLOADER delivers the CASTLESTEALER infostealer through malicious Google Ads campaigns, achieving remarkably low detection rates. The loader employs multiple obfuscation layers including control-flow flattening, opaque predicates, and mixed Boolean-Arithmetic techniques, along with self-modifying decryption stubs and abuse of the Windows .reloc section for shellcode staging. Distribution occurs via malvertising impersonating Node.js installations, redirecting victims through intermediary domains to Storj-hosted batch scripts. The loader implements five anti-VM and language checks, including CIS-region and Russian-language exclusions, suggesting a financially motivated Russian-speaking threat actor. OXLOADER uses DonutLoader to deliver the .NET-based CASTLESTEALER payload in memory, evading traditional detection mechanisms through deliberate engineering choices.
Tags
Date
- Created: June 19, 2026, 12:03 a.m.
- Published: June 19, 2026, 12:03 a.m.
- Modified: June 19, 2026, 8:39 a.m.
Indicators
- de4f51649ec1a33071854aefe93ffb3fc225e19f802d8dd914676dd5dfef2615
- c85f2765a6c3c3f3907c17e57df12f8f68826f74bff3bbfd272af50666d065fe
- 39019279686c820c3af5684012a0085a7e2109f612c9fab886dd0577ace5b5c6
- fdfc7831e5c24cfa80152860dfe8c056ba079f7df1393bf6bb7b18ed974eda37
- 9a9939dff297997732aaade9b243d695632cbd64033c5fbcb9de3d09b7e6c28d
- 4ec9d9d4d10ad78fc6d7bda7cb17d52984878ccd2dd4302fd1cef152313b9741
- https://link.storjshare.io/raw/jv5uebuqwzfpmtahj34q753ptykq/node/BATPackageBulderSetup.bat
- http://app.miloyannopoulos.com/download?subid1=download
- http://app.miloyannopoulos.com/download
- https://link.storjshare.io/raw/jvsmdybqmvwep2oawbobp6ub7aza/node/node-v24.15.0-x64-86.exe
- http://link.storjshare.io/raw/jwwvr4oskkkjsgevt774ta62ehya/ruslan/aBsvwbdas.exe
- http://link.storjshare.io/raw/jux4e4ky5mruo4jkxsssp42sau4q/ruslan/BATPackageBuilderSetup.bat
Attack Patterns
- DonutLoader
- CASTLESTEALER
- OXLOADER
Additional Informations
- node-js.prentiva99.info
- United States of America